Confirmed topic projection

Agentic SOC

Systems with confirmed investigation, triage, orchestration, or response assertions for security operations.

Human reviewed 2026-08-27 · subjects: alert-triage, autonomous-investigation, remediation

Systems in this topic

Cisco

Cisco Instant Attack Verification

EARLYUNKNOWNUNKNOWN

AFFIRMED — Cisco Instant Attack Verification automates evidence gathering, classification, recommendation, and reporting.

Conifers.ai

Conifers CognitiveSOC

EMERGINGUNKNOWNUNKNOWN

AFFIRMED — CognitiveSOC integrates intelligence, hunting, detection engineering, investigation, and remediation workflows.

Palo Alto Networks

Cortex AgentiX

EARLYUNKNOWNAPPROVAL-GATED

AFFIRMED — Cortex AgentiX agents can investigate threats and execute multi-step security tasks.

D3 Security

D3 Morpheus

EMERGINGUNKNOWNUNKNOWN

AFFIRMED — Morpheus performs investigation, triage, and response using one reasoning engine.

Dropzone AI

Dropzone AI SOC Analyst

EARLYUNKNOWNUNKNOWN

AFFIRMED — Dropzone AI autonomously investigates supported security alerts.

AFFIRMED — A CSA study compared analyst performance with and without Dropzone AI in simulated scenarios.

Google

Google Threat Hunt Agent

EARLYUNKNOWNUNKNOWN

AFFIRMED — The Google Threat Hunt Agent autonomously executes proactive hunts after analyst initiation.

SentinelOne

Purple AI Agentic Investigation

EMERGINGUNKNOWNUNKNOWN

AFFIRMED — Purple AI Agentic Investigations collects evidence and produces an AI verdict after manual or eligible automatic triggering.

Microsoft

Security Alert Triage Agent

EARLYUNKNOWNUNKNOWN

AFFIRMED — The Security Alert Triage Agent classifies supported alerts using contextual LLM analysis.

Microsoft

Microsoft Security Copilot Agents

EARLYUNKNOWNUNKNOWN

AFFIRMED — Security Copilot agents automate scoped security tasks in response to user requests or system events.

Simbian

Simbian AI NetSecOps Agent

EARLYHIGH-AUTONOMYBROAD-WRITE / NOT-BOUNDED

AFFIRMED — Simbian claims its NetSecOps Agent can make firewall policy changes and block threats without human intervention.

PARTIAL — Public vendor material states no human intervention for the documented NetSecOps actions; constraint details remain UNKNOWN.

Reviewed analysis

Action authority is the comparison buyers actually need

A governed comparison of read-only, recommendation, approval-gated, and bounded-autonomous security agents.

Why most agentic SOC evidence is still early

The maturity ladder separates product documentation from reproducible and independent validation.

Google SecOps has three different agent operating models

TIN, Threat Hunt Agent, and Detection Engineering Agent differ in trigger, runtime, and write authority.

Microsoft spans assistive triage, coordinated defense, and vulnerability research

Security Copilot agents, Project Perception, and MDASH solve different classes of work.